Bug ID 723847: Disable flow if no protocol inspection profile is attached.

Last Modified: Nov 07, 2022

Bug Tracker

Affected Product:  See more info
BIG-IP AFM(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 13.1.5, 13.1.5.1, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1

Fixed In:
14.1.0

Opened: Jun 11, 2018
Severity: 3-Major

Symptoms

If protocol inspection profile is attached with no compliance checking or signatures enabled, the system still processes all the packets through the IPS library.

Impact

Potential performance degradation.

Conditions

-- Protocol inspection profile is defined and attached to a virtual server. -- The profile contains no inspections.

Workaround

If no inspections are needed, then remove the protocol inspection profile from the virtual server. Otherwise, there is no workaround.

Fix Information

If no inspections are enabled, there is no performance degradation when attaching the protocol-inspection profile.

Behavior Change